Aggregator
Cross-Border Payments on Crypto Infrastructure: The $857 Billion Opportunity
21 hours 38 minutes ago
Cross-Border Payments on Crypto Infrastructure: The $857 Billion Opportunity Behind the Financial Su
Wordpress wp2shell 未授权RCE(CVE-2026-63030 / CVE-2026-60137)
21 hours 39 minutes ago
2026年了,在AI时代下总感觉什么都有可能,但是看到Wordpress居然能有原生未授权RCE还是感觉不可思议。Wordpress算是我曾经深度研究过的php源码之一,虽然wp架构复杂但是开发习惯很好,封装也比较严格,尤其是对权限的分割都做得很好,在5.0之后我一直认为wp不太可能出未授权的大漏洞了。
但很快,这个漏洞的挖掘者通过两个漏洞的组合就实现了这不可思议的一幕。
据说作者用AI完成了这个漏洞挖掘,并获得了50w刀的赏金(我没有求证,听说)。
- https://bugbunny.ai/blog/wordpress-7-0-2-rce-deep-dive#three-fixes-for-three-broken-assumptions
- 影响版本:WordPress 6.9.0-6.9.4、7.0.0-7.0.1
接下来我们就古法分析一下这个漏洞具体是怎么回事。
LoRexxar
Why Digital Forensic Reports Don’t Survive Cross-Examination
21 hours 40 minutes ago
A forensic report is not a summary of finished work. It’s a
自托管 AI 智能体的自状态攻击:操作系统防御能走多远?
21 hours 41 minutes ago
error code: 521
南鸟岛附近海底淤泥中检出多种中重稀土
21 hours 49 minutes ago
南鸟岛附近海底淤泥中检出多种中重稀土日本海洋研究开发机构24日宣布,深海探测船 “地球” 号在南鸟岛附近深海海底实施的稀土采掘试验中,从采集到的淤泥中检测出多种更珍贵且高科技产品不可或缺的“中重稀土元
诚邀渠道合作伙伴共启新征程
21 hours 53 minutes ago
【火绒安全周报】AI失控后入侵知名企业/韩国外交系统遭黑客攻击
21 hours 53 minutes ago
【火绒安全周报】AI失控后入侵知名企业/韩国外交系统遭黑客攻击
火绒小问答——「企业版」Syslog数据导出
21 hours 53 minutes ago
火绒小问答——「企业版」Syslog数据导出
防窃密可溯源 火绒构建终端数据安全审计完整防线
21 hours 53 minutes ago
防窃密可溯源 火绒构建终端数据安全审计完整防线
补丁没死,但不再是核心防御手段
21 hours 53 minutes ago
环境异常 当前环境异常,完成验证后即可继续访问。 去验证
Wordpress7.0 wp2shell 未授权RCE(CVE-2026-63030 / CVE-2026-60137)
21 hours 54 minutes ago
2026年了,在AI时代下总感觉什么都有可能,但是看到Wordpress居然能有原生未授权RCE还是感觉不可思议
CVE-2026-16519 | GeoVision GV-IP Device Utility up to 9.0.7.0 uncontrolled search path
21 hours 55 minutes ago
A vulnerability was found in GeoVision GV-IP Device Utility up to 9.0.7.0 and classified as critical. Affected is an unknown function. Executing a manipulation can lead to uncontrolled search path.
This vulnerability is handled as CVE-2026-16519. It is possible to launch the attack on the local host. There is not any exploit available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-15665 | wpmanageninja Fluent Support Plugin up to 2.3.0 on WordPress Shortcode redirect-to cross site scripting
21 hours 56 minutes ago
A vulnerability has been found in wpmanageninja Fluent Support Plugin up to 2.3.0 on WordPress and classified as problematic. This impacts an unknown function of the component Shortcode Handler. Performing a manipulation of the argument redirect-to results in cross site scripting.
This vulnerability is known as CVE-2026-15665. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-15653 | meIsle Visualizer Plugin up to 4.0.5 on WordPress backend-title cross site scripting
21 hours 57 minutes ago
A vulnerability, which was classified as problematic, was found in meIsle Visualizer Plugin up to 4.0.5 on WordPress. This affects an unknown function. Such manipulation of the argument backend-title leads to cross site scripting.
This vulnerability is traded as CVE-2026-15653. The attack may be launched remotely. There is no exploit available.
vuldb.com
CVE-2026-15464 | ThimPress WP Hotel Booking Plugin up to 2.3.2 on WordPress Shortcode widget_search cross site scripting
21 hours 58 minutes ago
A vulnerability, which was classified as problematic, has been found in ThimPress WP Hotel Booking Plugin up to 2.3.2 on WordPress. The impacted element is an unknown function of the component Shortcode Handler. This manipulation of the argument widget_search causes cross site scripting.
This vulnerability appears as CVE-2026-15464. The attack may be initiated remotely. There is no available exploit.
vuldb.com
CVE-2026-15334 | cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress cross site scripting
21 hours 59 minutes ago
A vulnerability classified as problematic was found in cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress. The affected element is an unknown function. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-15334. The attack can be launched remotely. No exploit exists.
vuldb.com
CVE-2026-15333 | cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress cozyCustomFont cross site scripting
22 hours ago
A vulnerability classified as problematic has been found in cozythemes Cozy Blocks Plugin up to 2.2.11 on WordPress. Impacted is an unknown function. The manipulation of the argument cozyCustomFont leads to cross site scripting.
This vulnerability is documented as CVE-2026-15333. The attack can be initiated remotely. There is not any exploit available.
vuldb.com
CVE-2026-15755 | 100plugins Open User Map Plugin up to 1.4.45 on WordPress Shortcode cross site scripting
22 hours 1 minute ago
A vulnerability described as problematic has been identified in 100plugins Open User Map Plugin up to 1.4.45 on WordPress. This issue affects some unknown processing of the component Shortcode Handler. Executing a manipulation of the argument Shortcode can lead to cross site scripting.
This vulnerability is registered as CVE-2026-15755. It is possible to launch the attack remotely. No exploit is available.
vuldb.com
CVE-2026-15648 | berocket Brands for WooCommerce Plugin up to 3.8.8 on WordPress Shortcode width cross site scripting
22 hours 2 minutes ago
A vulnerability marked as problematic has been reported in berocket Brands for WooCommerce Plugin up to 3.8.8 on WordPress. This vulnerability affects unknown code of the component Shortcode Handler. Performing a manipulation of the argument width results in cross site scripting.
This vulnerability is cataloged as CVE-2026-15648. It is possible to initiate the attack remotely. There is no exploit available.
vuldb.com